Connectivity
Workloads can find and reach one another regardless of placement.
Investigation 024 - Cluster Networking Principles
The flat network solved communication. It never decided whether a public frontend, payment processor, customer database, and reporting job should all trust one another equally.
Begin the investigation downPrologue
An office without locked rooms makes movement effortless. It also treats payroll, customer records, and public reception as one trust domain.
Every workload can find and reach every other workload.
Anything inside the platform deserves equal access.
Responsibilities and sensitivity diverge while reachability stays identical.
How can selected paths be denied without dismantling the flat network?
First Principles
A network can correctly deliver a packet and still enable a communication the platform should prohibit. Connectivity and authorization are independent contracts.
Workloads can find and reach one another regardless of placement.
No platform declaration says which workload relationships are permitted.
Routing capability can exist while policy prevents a prohibited communication outcome.
Unrestricted opportunity is not a network failure. It is a missing platform contract.
Naive Architecture
The simplest communication policy is no policy. Every path is available, no team waits for a rule, and new services communicate immediately.
Communication works from the first deployment.
The same small team owns and validates every workload.
Additional controls would add cost without solving a present problem.
The Architecture That Almost Worked
Each service already authenticates callers. Add a local allowlist and let every application reject communication it considers inappropriate.
The application can reject a caller after the connection arrives. The platform cannot verify that every team performs the check.
Breaking Our Design
Each experiment begins from its own state, earns one architectural step, and stops before the next episode's answer.
Pressure. Five workloads with different responsibilities and sensitivity share identical reachability.
Prediction. If internal placement implies trust, equal reachability should match equal consequence.
Reveal responsibilities and compare access.
Sensitivity differs; reachability does not.
Connectivity silently became trust.
The platform needs an explicit authorization question.
What happens when one workload is compromised?
No compromise or isolation solution appears here.
Pressure. One public frontend is compromised inside an otherwise functioning flat network.
Prediction. Cluster size should not change the consequence of compromising the same workload.
Model 10, 100, and 500 workloads.
Potential targets are N-1: 9, 99, 499.
Existing relationships expand opportunity.
Potential blast radius follows reachable relationships.
Who can enforce a uniform boundary?
Detection remains delayed and unresolved.
Pressure. Four teams implement per-application allowlists, but every application receives the connection before its code can reject it.
Prediction. Independent application ownership should produce uniform protection the platform can verify.
Omit one check across four teams.
The platform cannot verify uniform protection.
Perfect application behavior became an invariant.
Declare authorization separately as platform-owned desired state.
Observe enforcement, then probe a denied path.
Syntax, rule semantics, and mechanism remain deferred.
The Turning Point
The policy constrains communication outcomes. It does not replace the network beneath them.
The Network Isolation Contract
A mature platform preserves the flat routing foundation while governing which communication attempts are authorized to succeed.
Addresses, routes, and discovery retain their underlying capability. Policy enforcement prevents prohibited communication, so denied workload pairs do not have an authorized effective path.
Desired communication relationships exist independently of application code as platform-owned state.
The platform prevents prohibited communication before application business logic must reject it.
Connectivity establishes routing capability. Authorization determines the permitted communication outcome.
A compromise retains only the communication relationships intentionally authorized for that workload group.
Isolation does not prevent compromise. It limits the reachable opportunities available afterward.
Only Now: Kubernetes
Kubernetes NetworkPolicy controls layer 3 and layer 4 traffic involving Pods. Its selectors target Pods and namespaces, and its IP blocks target CIDR ranges. It does not target Services by name.
A supporting network plugin must implement enforcement. Creating a NetworkPolicy resource alone may have no effect. Applicable policies combine additively, and evaluation order does not change the result.
Policy handling is asynchronous. Existing or newly created Pods can temporarily observe lag or inconsistent application while a distributed plugin converges. The Kubernetes API exposes no exact signal for when a policy has been applied everywhere.
This investigation does not teach syntax, default-deny patterns, or CNI-specific mechanisms. NetworkPolicy does not provide TLS, Service-name targeting, guarantees for every protocol, compromise detection, or enforcement observability.
The architecture is platform-owned declarative isolation. NetworkPolicy realizes a bounded L3/L4 portion of it.
Engineering Reflection
Universal reachability enables communication. Declarative isolation governs it. A resilient platform requires both.
A cohesive team with a few uniformly trusted workloads may gain nothing from another policy layer.
Public entry points, sensitive workloads, multiple teams, tenants, or regulatory boundaries make unrestricted access unnecessary risk.
Communication declarations become another platform artifact.
Engineers must describe legitimate workload relationships.
An incorrect declaration can interrupt valid communication.
Troubleshooting separates routing capability from authorization outcome.
No. It remains the correct reachability foundation. The missing responsibility was authorization.
No. Detection can be delayed and partial. Isolation bounds opportunity without claiming to identify the attacker.
Investigation Exercise
Predict the possible targets available to one compromised frontend in each design.
Draw the same four workloads first with every path open, then with only necessary paths authorized.
Trace possible connection attempts without assuming every attempt compromises its target.
The vulnerability is unchanged. Only the opportunities after compromise differ.
Bridge to Movement IV
Every workload can discover and reach the others it needs.
Communication authorization is declared separately and enforced by the platform.
A compromise no longer inherits every possible path by default.
But every process loses what it held in memory when it stops.
State must outlive the process that produced it.
Movement III closes with governed communication. Movement IV opens with information that must survive execution.
This investigation inherits the book's separation of desired state from observed state and its decomposition of independently owned control responsibilities. Control theory supplies the feedback-loop model; Borg and Omega provide lineage for decomposition around shared state. Applying that inheritance to communication boundaries does not claim Borg or Omega invented Kubernetes NetworkPolicy.